Man, I never hear good security things about npm
AUR packages compromised with Infostealer and Rootkit
11–20 of 234 posts
Re: AUR packages compromised with Infostealer and Rootkit
#12Here's an easy script to scan for compromised packages: https://cscs.pastes.sh/aurvulntest20260611.sh Not my script. It's easy to read/parse. Never pipe a script directly to bash.
It isn't guaranteed that the list is conclusive. Always check PKGBUILD and sources, AUR is not to be trusted for the most part. I'm actually more surprised that such compromise hasn't happened earlier.
Re: AUR packages compromised with Infostealer and Rootkit
#13Here's an easy script to scan for compromised packages: https://cscs.pastes.sh/aurvulntest20260611.sh Not my script. It's easy to read/parse. Never pipe a script directly to bash.
comm -1 -2
It's never a bad time to learn about comm(1).Re: AUR packages compromised with Infostealer and Rootkit
#14Re: AUR packages compromised with Infostealer and Rootkit
#15AUR doesn't guarantee security, its upto the user to use AUR & verify before installing anything, its very evident why arch is not used in enterprise solutions.
Re: AUR packages compromised with Infostealer and Rootkit
#16AUR doesn't guarantee security, its upto the user to use AUR & verify before installing anything, its very evident why arch is not used in enterprise solutions.
Re: AUR packages compromised with Infostealer and Rootkit
#17Re: AUR packages compromised with Infostealer and Rootkit
#18Man, I never hear good security things about npm
This doesn't really have anything to do with npm.
>The result is a rather long list of ~408 packages all doing npm install atomic-lockfile something something
[0] https://lists.archlinux.org/archives/list/aur-general@lists....
Re: AUR packages compromised with Infostealer and Rootkit
#19Re: AUR packages compromised with Infostealer and Rootkit
#20Internet archive URL: https://web.archive.org/web/20260611213640/https://aur.archl...